ChildProcessSecurityPolicy::IsWebSafeScheme doesn't work right with blob/filesystem URLs |
||||||
Issue descriptionChildProcessSecurityPolicy::IsWebSafeScheme(std::string&) does not have enough information to render an appropriate judgment for blob and filesystem URLs. We should change it to accept an URL instead.
,
May 1 2017
Sounds like this is causing us to put subframe blob URLs into OOPIFs, even if they are same origin (in --site-per-process). I can repro this manually on 60.0.3086.0 with --site-per-process when opening src/third_party/WebKit/LayoutTests/storage/indexeddb/blob-valid-after-deletion.html in a tab. I see a "Subframe: blob:" line in the Chrome Task Manager. This explains the test failure in issue 717092 .
,
Jun 5 2017
,
Dec 6 2017
Any progress here? Just wondering if I get to resolve issue 717092 any time soon. :)
,
Feb 12 2018
ping?
,
Feb 12 2018
sub-frame blob URLs should always be same-origin (although the spec doesn't currently say so). Not sure if that helps here?
,
Sep 20
,
Sep 26
,
Jan 11
This issue has been marked as started, but has no owner. Making available. |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by creis@chromium.org
, May 1 2017